CVE-2004-1714

BlackICE PC Protection and Server Protection installs (1) firewall.ini, (2) blackice.ini, (3) sigs.ini and (4) protect.ini with Everyone Full Control permissions, which allows local users to cause a denial of service (crash) or modify configuration, as demonstrated by modifying firewall.ini to contain a large firewall rule.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:iss:blackice_pc_protection:3.6cbd:*:*:*:*:*:*:*
cpe:2.3:a:iss:blackice_pc_protection:3.6cbr:*:*:*:*:*:*:*
cpe:2.3:a:iss:blackice_pc_protection:3.6cbz:*:*:*:*:*:*:*
cpe:2.3:a:iss:blackice_pc_protection:3.6cca:*:*:*:*:*:*:*
cpe:2.3:a:iss:blackice_pc_protection:3.6ccb:*:*:*:*:*:*:*
cpe:2.3:a:iss:blackice_pc_protection:3.6ccc:*:*:*:*:*:*:*
cpe:2.3:a:iss:blackice_pc_protection:3.6ccd:*:*:*:*:*:*:*
cpe:2.3:a:iss:blackice_pc_protection:3.6cce:*:*:*:*:*:*:*
cpe:2.3:a:iss:blackice_pc_protection:3.6ccf:*:*:*:*:*:*:*
cpe:2.3:a:iss:blackice_pc_protection:3.6ccg:*:*:*:*:*:*:*
cpe:2.3:a:iss:blackice_server_protection:3.5cdf:*:*:*:*:*:*:*
cpe:2.3:a:iss:blackice_server_protection:3.6cbz:*:*:*:*:*:*:*
cpe:2.3:a:iss:blackice_server_protection:3.6cca:*:*:*:*:*:*:*
cpe:2.3:a:iss:blackice_server_protection:3.6ccb:*:*:*:*:*:*:*
cpe:2.3:a:iss:blackice_server_protection:3.6ccc:*:*:*:*:*:*:*
cpe:2.3:a:iss:blackice_server_protection:3.6ccd:*:*:*:*:*:*:*
cpe:2.3:a:iss:blackice_server_protection:3.6cce:*:*:*:*:*:*:*
cpe:2.3:a:iss:blackice_server_protection:3.6ccf:*:*:*:*:*:*:*
cpe:2.3:a:iss:blackice_server_protection:3.6ccg:*:*:*:*:*:*:*
cpe:2.3:a:iss:blackice_server_protection:3.6cch:*:*:*:*:*:*:*
cpe:2.3:a:iss:blackice_server_protection:3.6cno:*:*:*:*:*:*:*

History

26 Jan 2024, 17:21

Type Values Removed Values Added
CVSS v2 : 2.1
v3 : unknown
v2 : 2.1
v3 : 7.1
CWE NVD-CWE-Other CWE-732
References () http://lists.grok.org.uk/pipermail/full-disclosure/2004-August/025112.html - Exploit, Patch, Vendor Advisory () http://lists.grok.org.uk/pipermail/full-disclosure/2004-August/025112.html - Not Applicable
References () http://marc.info/?l=bugtraq&m=109223751031166&w=2 - () http://marc.info/?l=bugtraq&m=109223751031166&w=2 - Mailing List
References () http://www.securityfocus.com/bid/10915 - Exploit, Vendor Advisory () http://www.securityfocus.com/bid/10915 - Broken Link, Exploit, Third Party Advisory, VDB Entry, Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/16959 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/16959 - Third Party Advisory, VDB Entry

Information

Published : 2004-08-11 04:00

Updated : 2024-01-26 17:21


NVD link : CVE-2004-1714

Mitre link : CVE-2004-1714

CVE.ORG link : CVE-2004-1714


JSON object : View

Products Affected

iss

  • blackice_server_protection
  • blackice_pc_protection
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource